FINDING · DETECTION

When a censor controls the WebRTC signaling plane, it can mount MITM attacks against CRON's vanilla covert encoding because the encoding 'fully replaces the video payload with an apparently random covert data signal that results in a scrambled video image at the receiver's endpoint.' By replaying the captured video through a WebRTC gateway, the censor obtains direct visual evidence of payload manipulation.

From 2020-barradas-towardsTowards a Scalable Censorship-Resistant Overlay Network based on WebRTC Covert Channels · §4.2 · 2020 · Distributed Infrastructure for Common Good

Implications

Tags

censors
cnir
techniques
active-probingdpi
defenses
webrtc-pluggable

Extracted by claude-sonnet-4-6 — review before relying.